CVE-2025-59398CWE-392

The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 255 characters, because a CiString<255>…

Low · published September 15, 2025

CVSS v3.1
3.1
EPSS
0%
Percentile
15.0
In the wild
Unconfirmed
What it is

The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 255 characters, because a CiString<255> object is created with StringTooLarge set to Throw.

The record
Technical detail
CVSS v3.1
3.1 · LOW
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS v4.0
Not supplied
EPSS
0.00240 · 15.0th percentile
Weakness
CWE-392 · Missing Report of Error Condition
Published
2025-09-15T00:00Z
EPSS history
Timeline
  • 15 SEP 00:00Z
    The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 255 characters, because a CiString<255>…
    cvelistv5